Skip to content
Back to perspectives

Perspective

Why security policies matter in business

I attended a Demateus seminar on dematerialization and electronic archiving last week and, in discussing the various measures for protecting confidential information, it occurred to me to write a blog post on how important it is to implement and apply a security policy within a business. A good many businesses apply no security policy, and do not know the extent of the information resources they hold either. Given how information technology is evolving, adopting a firm information security policy is not only prudent but strategic.

Although the subject is a broad one and the benefits may be many, we will limit ourselves to 4 points that strike us as essential:

1) Identifying and managing security risks

Without an effective, regularly updated security policy, a business runs several risks, such as the destruction of documents that have to be retained, or the inadvertent alteration of data. One function of a security policy is therefore to anticipate security risks and to provide for measures to reduce them, if not eliminate them. The risks will of course differ between an SME and a large organization. But it is undeniable that sound risk management will limit the threats and so head off the impacts, whether legal or economic.

To assess a system’s risks properly, one must not only assess its technical vulnerabilities but also carry out a preliminary exercise of classifying and quantifying the information. The purpose is to identify and categorize all the personal and confidential information an organization holds, and then to determine the security measures that ought to be put in place for each type of information. Although the law does not prescribe the exact nature of the security measures required to protect information, it does provide that “a person carrying on an enterprise must take the security measures necessary to ensure the protection of the personal information collected, used, released, kept or destroyed and that are reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored”[1].

Sound risk management also means setting rules for employees’ use of workstations and social media, so as to protect the employer and to limit the damage that could flow from an unauthorized disclosure of information. A policy should also set out which technologies are to be put in place to guarantee the authenticity of the documents issued, how encryption keys are managed, access rights within the business and the security incident management process, among others. Note that incident management may be the subject of a separate policy or be incorporated into a general information security policy.

2) Ensuring compliance in the handling of information

Nothing in the law specifies what a security policy must contain. Various rules on the handling of information have, however, been laid down by the legislature, particularly as regards the confidentiality, integrity and accessibility of data. For example, the Act to establish a legal framework for information technology obliges organizations to preserve the integrity of technology-based documents so that they can retain their probative value. Account must also be taken of the provisions of the Act respecting the protection of personal information in the private sector concerning, for instance, the requirement of consent to the collection of personal information and the rights of access to it and of its destruction. Specific rules on data retention or preservation may also be laid down by statutes particular to certain fields, such as tax legislation, intellectual property rights, the statutes governing medical data, and certain limitation periods. A security policy therefore works out the rules and procedures to be implemented in the light of all the risks identified and of the legislative obligations, both general and specific to certain types of information.

It is also worth noting that, although there is at present no explicit obligation in Québec to preserve documents in anticipation of litigation, the Sedona Canada Principles provide that, as soon as litigation is reasonably foreseeable, a business should “immediately take reasonable and good faith steps to preserve potentially relevant electronic documents”[2]. In that connection, note that art. 4.1 of Québec’s Code of Civil Procedure provides that the parties to a proceeding must act in good faith and must not cause prejudice to another person in an excessive or unreasonable manner.

3) Optimizing the management of information resources

As Jean-Marc Rietsch explained so well at the Demateus seminar, the retention and archiving of data are essential elements of the digital economy. Sound management of resources does indeed allow information to be organized so as to optimize the processes that handle it. A business should therefore take care not to retain information unnecessarily and, by the same token, make sure the data does not prejudice the business in managing ediscovery, should it arise. As the lawyer Isabelle Renard pointed out, the harder information is to manage, the more expensive litigation is liable to be. A security policy thus makes it possible, in a sense, to quantify the documentary process.

What is more, it can be very much to a business’s advantage to apply a security incident management policy. Documenting incidents makes it possible to carry out a post-mortem analysis and to establish whether the incident could have been avoided. An assessment of the financial losses and of the impacts flowing from the incident can also support recommendations to management on improving preventive activity, and serve as evidence in a contentious setting, should it arise.

4) Promoting consistency in the management and security of information

Implementing a security policy will serve to standardize the handling of information and to set specific rules for it. On a broader scale, however, it is important to provide for a framework policy on information governance and management, whose purpose is to define the business’s general direction in handling and securing its information assets. It records, for example, the various roles and responsibilities and certain references to technical standards for information management (for instance, the ISO/IEC 27001 standard). Every employee, manager or agent of the business then has an overall view and a plan of action that they must know and put into effect. A framework policy ensures that documents are all handled consistently by the various departments, in accordance with the business’s rules of ethics and governance. Note that where security policies apply across a whole organization, they normally have to be endorsed by the business’s board of directors.

****

Ideally, every organization should designate someone responsible for information security, whose main task is to make sure that information resources and access rights comply with the security policies the organization has put in place. What is more, implementing and strategically planning the management of information can prove beneficial in terms of the digital economy.


[1] S. 10, Act respecting the protection of personal information in the private sector, c. P-39.1.

[2] The Sedona Canada Principles are available at the following address: <https://www.lexum.com>.

Send us a message

Only your email is required. Pick a subject, add a note, and send.

Incident in progress? Call the 24/7 line instead of waiting for a reply: +1 450 681-1681, extension 277